Module 09 · 24 sections

Intrusion Detection & UL 2050 / Extent 3

How SCIF, SAPF and NISPOM intrusion detection works: Extent 3, UL 2050 certificates, sensors, power, response, testing and records.

On this page
  1. 09.01What an IDS must accomplish in a SCIF
  2. 09.02What Extent 3 actually means
  3. 09.03The 12 numbers every SCIF IDS installer should know
  4. 09.04Sensors: UL 634 Level II switches and UL 639 motion detection
  5. 09.05Premise control unit: location, display and reset
  6. 09.06Integrated and networked IDS, hosts and remote terminals
  7. 09.07Modes of operation: armed, disarmed and maintenance
  8. 09.08Electrical power: 24 hours uninterruptible
  9. 09.09Monitoring stations and who may staff them
  10. 09.10Alarm response times and Security-in-Depth
  11. 09.11Maintenance, semiannual testing and false alarm limits
  12. 09.12Installation and acceptance testing
  13. 09.13IDS records retention
  14. 09.14UL 2050 overview: edition, scope and listing categories
  15. 09.15The CS-ASD-NISS form, the certificate and investigator response times
  16. 09.16UL audits and how to verify a UL 2050 certificate
  17. 09.17UL 681 vs UL 2050 extents: what is and isn't known
  18. 09.18Related UL standards and their roles
  19. 09.19NISPOM 32 CFR 117.15 intrusion detection requirements
  20. 09.20SAPF intrusion detection under DoDM 5205.07 and the DCSA checklist
  21. 09.21Communicators, line security and the FIPS 140-2 transition
  22. 09.22SCIF vs SAPF vs NISPOM open storage vs GSA container
  23. 09.23Common IDS findings at accreditation
  24. 09.24Vetting a UL 2050 alarm company
09.01

What an IDS must accomplish in a SCIF

The requirements are in IC Tech Spec Chapter 7. The v1.5 and v1.5.1 change histories list no Chapter 7 changes, so the Chapter 7 wording and paragraph numbers quoted in this module come from a public v1.4 copy. Confirm critical wording against v1.5.1. ICS 705-1 sets the standard: "IDS installation, related components, and monitoring stations shall comply with Underwriters Laboratories (UL) 2050 Extent 3 standards."

Job Requirement Tech Spec
Protect when unoccupied "SCIFs shall be protected by IDS when not occupied." 7.A.1.a
Cover the interior Interior areas, including walls next to non-SCI space. The AO may accept layered controls instead. 7.A.1.b
Watch uncontrolled doors Doors that have no access control and are not under constant observation are monitored continuously 7.A.1.c
Stand alone "IDS's shall be separate from, and independent of, fire, smoke, radon, water, and other systems." 7.A.2.h
Rank first When the IDS is integrated with access control, ACS notifications rank below IDS alarms 7.A.2.i
No eavesdropping IDS components may not have audio or video capability unless the AO approves it with countermeasures 7.A.2.l
Hold the alarm "Alarm activations shall remain displayed locally until cleared by an authorized SCI-cleared individual." Auto-reset is disabled. 7.A.2.m–n
Plan for failure If any component fails, SCI-indoctrinated personnel occupy the SCIF or AO-approved measures apply. "IDS failure shall be addressed in the SCIF emergency plan." 7.A.1.d–e
Treat alarms as real "Alarm activations shall be considered an unauthorized entry until resolved." 7.C.1

The AO approves the IDS plans. Acceptance testing is required before accreditation (7.A.2.o). The IDS works alongside the FF-L-2740 combination lock and the perimeter construction and never replaces either one. Access control does not replace the IDS either. See: Doors, Locks & Security Containers and See: Access Control, Identity & Hirsch.

Sources IC Tech Spec Ch. 7 (v1.4 archive; text source) · IC Tech Spec v1.5.1 · ICS 705-1

09.02

What Extent 3 actually means

Source Exact wording
IC Tech Spec 7.A.2.b "Installation shall comply with an Extent 3 installation as referenced in UL 2050."
IC Tech Spec 7.A.2.c (paraphrase) Systems developed and used by the U.S. Government do not require UL certification but must comply with the Extent 3 installation requirements
UL instructions for Form CS-ASD-NISS "The 'extent of protection' is the designation used to describe the amount of alarm protection installed to protect a particular area, room or container."
Same instructions "Either an extent No. 3 or extent No. 5 is acceptable for use in either closed areas or alarmed rooms."
UL Form CS-ASD-NISS (closed area / alarmed room) "3" or "5 (Prior approval is required)"
CDSE SA501 student guide "Extent 3 requirements are the highest level of security for National Industrial Security Systems."

Extent 5. Under 32 CFR 117.15(d)(4)(ii), the CSA must give authorization on the alarm system description form for an installation that "provides a level of protection, e.g. UL's Extent 5, based on patrolling employees and CSA approval of security-in-depth." Extent 5 trades sensor coverage for patrols and layered controls. The Tech Spec has no Extent 5 option, so it never applies to a SCIF or SAPF.

Best public description of Extent 3 coverage. Before the rule lists Extent 5 as the exception, it sets this baseline: "all points of probable entry (perimeter doors and accessible windows) with magnetic contacts and motion detectors positioned in the probable intruder paths from the probable points of entry to the classified information." That sentence never says "Extent 3." Reading it as the Extent 3 description is an inference. On top of that baseline, ICD 705 requires UL 634 Level II switches and motion detection on every perimeter door, 24-hour backup power, and encrypted transmission.

Sources IC Tech Spec Ch. 7 · UL CS-ASD-NISS instructions · UL Form CS-ASD-NISS · 32 CFR 117.15 · CDSE SA501

09.03

The 12 numbers every SCIF IDS installer should know

These values come from the IC Tech Spec (Chapter 7 as quoted from the public v1.4 copy; Chapter 3 from v1.5.1), and they are the first numbers a reviewer looks for. Some items allow an alternative the AO approves, and any such alternative should be in writing.

# Requirement Value Cite
1 UL installation level UL 2050 Extent 3 7.A.2.b
2 Door switch UL 634 listed HSS, Level II (new accreditations) 7.A.2.d
3 Motion sensors UL 639 listed; HSS and motion on every perimeter door 7.A.2.d; 7.A.3.a(7)
4 Entry delay at the primary door 30 seconds 7.A.3.a(6)
5 Backup power 24 hours uninterruptible 7.B.5
6 False alarms 1 per 30 days per IDS partition 7.A.2.p
7 Response force, closed storage 15 minutes 3.H(a)
8 Response force, open storage 15 minutes with SID; 5 minutes without 3.H(b); 32 CFR 2001.43
9 SCI-indoctrinated person on site 60 minutes (UL 2050) or AO-approved time 7.C.1.c
10 Service start after a trouble signal within 4 hours 7.C.2
11 Recurring IDS test Semiannual 7.D.3
12 Motion walk test pass alarm on 3 of every 4 consecutive four-step trials 7.D.3

Other numbers that come up often:

  • Test records, arm/disarm failure records and battery maintenance records are kept 2 years.
  • Networked IDS passwords are at least 12 characters and changed every six months, unless PIV/CAC authentication is used.
  • Duct and vent openings larger than 96 square inches need bars, grilles or baffles. IDS is not listed as a substitute.

Sources IC Tech Spec Ch. 7 · IC Tech Spec v1.5.1 (Ch. 2–3) · 32 CFR 2001.43

09.04

Sensors: UL 634 Level II switches and UL 639 motion detection

Tech Spec 7.A.2.d requires protection with "UL 639 listed motion sensors and UL 634 listed High Security Switches (HSS) that meet UL Level II requirements." New accreditations need Level II. Existing Level I switches may stay until major IDS modifications or upgrades. UFC 4-010-05 3-4.17.3.3 adds: "Level 2 rated switches only include Balanced Magnetic Switches." That is why HSS and BMS are used interchangeably in the field.

Rule Requirement Cite
Perimeter doors "SCIF perimeter doors shall be protected by an HSS and a motion detection sensor." 7.A.3.a(7)
Emergency exit doors "Emergency exit doors shall be alarmed and monitored 24 hours per day." Egress-only doors also need a local audible annunciator. 7.A.3.a(8); 3.E.4.c
Sensor location Inside the SCIF. Sensors outside the perimeter need AO approval and protected cabling. 7.A.3.a(1)–(2)
Failed sensor "Failed sensors shall cause immediate and continuous alarm activation until the failure is investigated and corrected." 7.A.3.a(3)
Dual technology Allowed if each technology reports alarms independently 7.A.3.a(4)
Quantity Enough to meet 7.A.2.d, or as the AO approves 7.A.3.a(5)
Plenums May be required above false ceilings or below false floors at overseas Category I and II locations. UFC: "Motion sensors are not normally required above false ceilings or below false floors." 7.A.3.a(5); UFC 3-4.17.3
HSS performance Alarms before the non-hinged side of the door opens farther than the door's thickness 7.D.3
Cabling outside the SCIF Encrypted line security, or ferrous conduit (EMT or rigid) with permanently sealed joints and no set screws. Service and junction boxes need GSA-approved locks. 7.A.2.e

UFC also calls for motion detection in "all Interior areas through which reasonable access to the asset could be gained." Lay out coverage so that no four-step path to the material goes undetected. Dead zones usually form behind tall cabinets, GSA containers and cubicle walls. CDSE SA501 applies the same rules to SAPFs: "All perimeter doors of your SAPF need to be protected by the IDS using HSS and motion sensors."

Sources IC Tech Spec Ch. 7 · UFC 4-010-05 · CDSE SA501

09.05

Premise control unit: location, display and reset

Requirement (Tech Spec 7.A.3.b) Para
"PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes." (1)
Arming and disarming use a device or procedure that validates the user, such as a PIN or credential (2)
Cabling from sensors to the PCU is dedicated to the system, stays within the SCIF, and complies with electrical codes and CNSS standards (3)
An alphanumeric display shows status continuously at the PCU and/or the monitoring station (4)
The PCU is installed where unauthorized people cannot observe it (5)
The PCU identifies and displays which sensors activated (6)
Immediate, continuous annunciation of intrusion, failed sensor, tamper, maintenance mode, and shunted or masked points (7)
Changes in power status (AC or backup) show locally and at the station (8)
SCI-indoctrinated personnel reset events after inspecting the SCIF; auto-reset is disabled (9)
Transmission to the monitoring station uses FIPS-certified encryption (10)
The SCI-cleared IDS administrator changes maintenance and master profiles, PINs and passcodes from their defaults (11)

The DoD design version is UFC 4-010-05 3-4.17.3.5: "Locate PCU within the Perimeter. Configure system to only allow cleared personnel located within the secure/protected area to initiate changes." The Fixed Facility Checklist asks two questions here: whether the PCU is inside the perimeter, and whether PCU status can be changed from outside IDS protection. A "yes" to the second question is a problem.

Co-located SCIFs that support the same IC element may share a partitioned PCU, with each partition acting as an independent control unit (7.A.2.f). The older-edition text also appears to extend this to SCIFs under a Co-Use Agreement, so confirm against v1.5.1. A Compartmented Area does not get its own partition: Tech Spec 2.C.4 states "Independent alarm systems shall not be installed in a CA." When one station monitors several systems, each system needs its own distinct audible and visible annunciation (7.A.2.g).

Sources IC Tech Spec Ch. 7 · UFC 4-010-05 · SCIF Fixed Facility Checklist v1.5 · IC Tech Spec v1.5.1 (2.C)

09.06

Integrated and networked IDS, hosts and remote terminals

Topic Requirement 7.A.3.c
USG networks Coordinate with the AO's CIO. The hosting system needs an Authority to Operate under the RMF (NIST SP 800-53). (1)
Host location The host is restricted, logically and physically, to SCI-cleared security staff. It sits in a "Physically Protected Space": a locked room with fixed walls, floor and ceiling, Commercial Grade 1 hardware and UL 437 high-security cylinders, "protected by a UL Extent 3 burglar alarm system and access control unless manned 24 hours" (2)(a)
Isolation Firewalls, VPNs, virtual routing tables and application-level security. Only secure, private transfers among the PCU, host, remote terminal and station. (2)(b)
Remote programming If any component can be programmed remotely, the network is continuously monitored, including network intrusion detection and prevention auditing (2)(c)
Secondary path Optional. Used to cut down on investigations of communication failures shorter than five minutes. Supervised like the primary path. A wireless path needs AO approval after consulting the CTTA. (2)(d)
Credentials Unique user IDs. Passwords of at least 12 characters (letters, numbers, special characters) changed every six months, or PIV/CAC certificate authentication. (2)(e)
Reporting Administrators report unauthorized modifications to the AO immediately (2)(f)
Transmission FIPS 140-2, VPN, or closed and sealed conveyance. FIPS 197 (AES) with AO approval. (2)(g)
Remote terminals Role-based permissions approved by the AO. Non-SCI-cleared personnel may not modify the IDS or ACS. Separate login beyond the host login. Failed logins logged. Remote sessions documented. Hosts and PCUs patched (USG: IAVA). (2)(h)

System variables and passwords are restricted to SCI-indoctrinated U.S. personnel (7.A.2.j). ACS events must never rank above IDS alarms (7.A.2.i).

Sources IC Tech Spec Ch. 7 · DCSA ISL 2006-02

09.07

Modes of operation: armed, disarmed and maintenance

Tech Spec v1.3 replaced the older "access/secure" terms with "arm/disarm." Many panels, forms and checklist titles still say access and secure.

Mode Rules Tech Spec
General "There shall be no remote capability for changing the mode of operation by non-SCI cleared personnel." Anyone who changes the mode is SCI-indoctrinated. 7.B.1
Disarmed (access) Authorized entry does not cause an alarm. "A record shall be maintained that identifies the person responsible for disarming the system." Tamper circuits and emergency-exit-door circuits stay armed. Some points can be armed while others are disarmed. 7.B.2
Armed (secure) The system is armed when the last person leaves, and a record shows who armed it. Each failure to arm or disarm is reported to the facility's security officials, and those records are kept two years. Any unauthorized entry sends an alarm to the station immediately. 7.B.3
Maintenance, shunt, mask The station is notified and logs the event. Only SCI-cleared administrators or the SSO can start maintenance mode. Shunted or masked points show at the station and reactivate at the next armed-to-disarmed transition. The SCI-cleared administrator sets the maintenance PIN. PEDs may connect for maintenance under SCI-cleared control. Remote diagnostics are logged. 7.B.4

DoD design criteria add two features that are often built into the IDS panel:

  • Duress (UFC 4-010-05 3-4.16): starts an alarm at the central monitoring station with "no audible or visual signal in the protected area."
  • Non-indoctrinated presence (UFC 3-4.15): a flashing or rotating light is approved, with controls inside the perimeter at each entrance.

Sources IC Tech Spec Ch. 7 · UFC 4-010-05 · Traditional Security Checklist (stigviewer)

09.08

Electrical power: 24 hours uninterruptible

When primary power fails, Tech Spec 7.B.5 requires the system to switch to emergency power automatically, without causing an alarm. "Twenty-four hours of uninterruptible backup power is required and shall be provided by batteries, an uninterruptible power supply (UPS), generators, or any combination."

Source Requirement
Tech Spec 7.B.5 24 hours. The PCU shows the active power source. The station shows power failures and changes.
UFC 4-010-05 3-4.17.3.7 "Provide twenty-four hours of uninterruptible standby power." "When an engine-generator is available for standby power, provide batteries for IDS that provide a minimum of four hours."
DCSA SAP checklist F-44 24-hour backup power documented in the FFC
Fixed Facility Checklist, Section E Generator hours and battery hours recorded separately
Tech Spec 7.C.2 Batteries maintained on the manufacturer's schedule; records kept two years

Battery calculation method (our method, built from the requirements above):

  1. List the standby current of the PCU, every sensor and keypad, the communicators and encryption modules, and any network switch or PoE device in the signal path.
  2. Use measured currents, not nameplate values. Multiply the total by 24 hours.
  3. Add the alarm-state current multiplied by the alarm duration that the panel's listing and the applicable UL standard require. That duration is not published publicly, so confirm it.
  4. Apply the manufacturer's temperature and aging derating, then pick the next larger battery size.
  5. Include the calculation in the FFC package.

Sources IC Tech Spec Ch. 7 · UFC 4-010-05 · DCSA SAP Compliance Checklist (Jan 2026) · SCIF Fixed Facility Checklist v1.5

09.09

Monitoring stations and who may staff them

Tech Spec 7.B.6 allows these stations: a government-managed station, an AO-operated station, a Government Contractor Monitoring Station (GCMS), a national industrial monitoring station, or a cleared commercial central station.

Operators must be U.S. citizens and trained alarm monitors. They must be eligible for a U.S. SECRET clearance and trained in how the system works and operates. DCSA SAP checklist item F-43 applies the same rule to SAPFs.

The NISPOM version is 32 CFR 117.15(d)(2). It requires "SECRET-cleared central station employees" in enough numbers to monitor each alarmed area, and continuous supervision "by a U.S. citizen who has eligibility for access to SECRET information."

UL 2050 station types (from the Edition 5 NISPPAC briefing):

Type Definition UL category
GCMS "A monitoring station that is operated by a defense contractor with the purpose of monitoring Industrial Security Systems." Systems must be "within 240 miles."
NIMS National Industrial Monitoring Station, for systems more than 240 miles away CRZM
Commercial UL central station Listed central station UUFX, CPVX or CVSU
Law-enforcement agency Needs alarm receiving equipment; provides monitoring and dispatch

GCMS and NIMS compliance covers:

  • physical protection
  • alarm receiving equipment
  • fire protection
  • clocks
  • primary and secondary power
  • communication circuits
  • personnel

Automation systems are tied to UL 1981. Stations that use packet-switched or managed voice networks "shall utilize communication services that deliver geographically diverse signal pathways, if possible."

Sources IC Tech Spec Ch. 7 · 32 CFR 117.15 · NISPPAC: UL 2050 types of monitoring · NISPPAC: automation systems · NISPPAC: communication infrastructure · DCSA SAP Compliance Checklist

09.10

Alarm response times and Security-in-Depth

Tech Spec 3.H: "Response times for Intrusion Detection Systems (IDS) shall meet 32 CFR Parts 2001 and 2004."

Storage condition Response force arrival Then
Closed storage 15 minutes (3.H(a)) An SCI-indoctrinated person arrives within 60 minutes (UL 2050) or the time the AO approves (7.C.1.c)
Open storage with Security-in-Depth Within 15 minutes of alarm annunciation (3.H(b)) Same
Open storage without Security-in-Depth 5 minutes (3.H(b)) Same

Security-in-Depth (SID) (Tech Spec 2.B) means layered security controls that the AO may accept. SID may change construction requirements and "extend security alarm response time to the maximum of 15 minutes." Examples from 2.B.3:

  • military installations, embassy compounds, and USG or contractor compounds with a dedicated response force
  • controlled buildings with separate building access controls, alarms and elevator controls
  • controlled office areas next to or around the SCIF that are protected by alarms
  • fenced compounds with access-controlled vehicle and/or pedestrian gates

Response procedure (7.C.1). Under a written support agreement, the response force protects the SCIF until SCI-indoctrinated personnel arrive. That person inspects the SCIF, tries to find the cause of the alarm, and resets the IDS before the response force leaves.

Fixed Facility Checklist, Section E, asks for:

  • who provides the initial response
  • whether responders are cleared
  • the written agreement with any external response force
  • the response time in minutes
  • whether response procedures are tested and records kept
  • whether the AO approved a catastrophic failure plan

Sources IC Tech Spec v1.5.1 (Ch. 2–3) · IC Tech Spec Ch. 7 · 32 CFR 2001.43 · SCIF Fixed Facility Checklist v1.5

09.11

Maintenance, semiannual testing and false alarm limits

Maintenance (Tech Spec 7.C.2)

  • Maintenance and repair personnel hold a TOP SECRET clearance or are escorted.
  • "Repairs shall be initiated by a service technician within 4 hours of the receipt of a trouble signal or a request for service."
  • Until repairs are done, SCI-indoctrinated personnel staff the SCIF 24 hours a day, unless the AO has approved documented alternate procedures.
  • Batteries are maintained on the manufacturer's schedule, and records are kept two years.
  • Network maintenance personnel inside the U.S. are U.S. persons with an escort. Outside the U.S. they hold a TS or SECRET clearance and are escorted.

Recurring testing (7.D.3): "Semi-annual IDS testing shall be conducted to ensure continued performance."

Test Method and pass criterion
Motion Each trial is four consecutive steps at one step per second, about 30 in ± 3 in per step, with a 3–5 second pause between trials. "An alarm shall activate at least three out of every four consecutive trials made by moving progressively through the SCIF."
HSS The alarm activates before the non-hinged side of the door opens farther than the door's thickness
Tamper Each equipment cover is tested for alarm in both secure and access modes

Test records list the test dates, who tested, the equipment tested, any malfunctions, and the corrective action. They are kept two years (DCSA SAP checklist F-27, citing Tech Spec 12.L.6).

False alarms (7.A.2.p): "False alarms shall not exceed one alarm per 30-day period per IDS partition." Common causes include:

  • HVAC diffusers blowing across PIR sensors
  • heaters in a sensor's field of view
  • microwave sensors that see through drywall into non-SCIF space

Sources IC Tech Spec Ch. 7 · DCSA SAP Compliance Checklist

09.12

Installation and acceptance testing

Topic Requirement Cite
Installers (U.S.) "Installation and testing within the U.S. shall be performed by U.S. companies using U.S. citizens." Tech Spec 7.D.1; SAP checklist F-32
Installers (overseas) U.S. TOP SECRET-cleared personnel, or SECRET-cleared personnel escorted by SCIF staff 7.D.1
Standards Tech Spec, UL 2050 and the manufacturer's specifications 7.D.2
Approval The AO approves system plans; acceptance testing is done before accreditation 7.A.2.o
NISPOM "CSA approval is required before installing an IDS." 32 CFR 117.15(d)(1)
Defaults Master and maintenance profiles, PINs and passcodes changed from factory settings 7.A.3.b(11)

What an acceptance test should prove (our checklist, based on Chapter 7):

  1. Every motion sensor passes the walk test at 3 of 4 trials.
  2. Every HSS trips within the door's thickness, emergency exits included.
  3. Opening every equipment cover in both modes triggers tamper.
  4. Intrusion, failed sensor, tamper, maintenance and shunt events annunciate at both the PCU and the station.
  5. With AC power removed, the system switches to backup without an alarm and shows the power change.
  6. Entry delay is 30 seconds or less, auto-reset is disabled, and alarms stay displayed until cleared locally.
  7. Encryption works end to end.

Fixed Facility Checklist, Section E, documents:

  • PCU make, model and location
  • tamper protection
  • HSS type
  • motion sensor make, model and location
  • whether the IDS extends beyond the perimeter
  • audio or video capability
  • whether the administrator is SCI-indoctrinated
  • line security and LAN/WAN use
  • generator and battery hours
  • monitoring station location
  • remote capabilities, automatic features and dial-out

Sources IC Tech Spec Ch. 7 · 32 CFR 117.15 · DCSA SAP Compliance Checklist · SCIF Fixed Facility Checklist v1.5 · ICD 705 construction: an end user's view (practitioner)

09.13

IDS records retention

Record Retention Cite
Failures to arm or disarm (reported to the security officer; the GSSO/CSSO for SAPFs) 2 years Tech Spec 7.B.3; DCSA SAP checklist F-28
IDS test and performance records 2 years Tech Spec 12.L.6; F-27
Battery maintenance 2 years 7.C.2
Person who armed and disarmed "A record shall be maintained"; retention per Chapter 12 7.B.2–7.B.3
Maintenance mode, shunt and mask events Logged by the monitoring station 7.B.4
Remote diagnostics after installation Logged 7.B.4
Remote sessions and failed logins (networked IDS) Logged; available to the AO 7.A.3.c(2)(h)
NISPOM alarm records: time of alarm, responder names, dispatch and arrival times, nature of the alarm, follow-up 12 months 32 CFR 117.15(d)(2)

The SCIF security officer or IDS administrator should be able to produce these on request:

  • arm and disarm records
  • failure-to-arm reports
  • semiannual test records
  • battery maintenance records
  • remote session logs
  • the IDS portion of the Fixed Facility Checklist
  • the response force agreement
  • the emergency or catastrophic failure plan

For SAPFs, DCSA checklist item F-42 also looks for the external response agreement. It should cover the response time, duties on arrival, SAPF points of contact, and how long responders stay on site.

Sources IC Tech Spec Ch. 7 · DCSA SAP Compliance Checklist · 32 CFR 117.15

09.14

UL 2050 overview: edition, scope and listing categories

Title and edition. UL Standards & Engagement sells the standard as UL 2050, National Industrial Security Systems. The Tech Spec uses a longer title: "…for the Protection of Classified Material." The current edition is Edition 6, published 7 April 2025 and revised 9 April 2025. Edition 5 (5 November 2010) is archived. UL 681 (Edition 15) and UL 827 (Edition 9) both reference UL 2050.

Scope as UL describes it. The standard "was developed in collaboration with U.S. federal security agencies." Its "technical requirements… describe the elements of alarm protection (intrusion detection) needed to coordinate with related security measures." A national industrial security system "is installed and is remotely monitored on alarm receiving equipment located in a government-contracted monitoring station, or an independently certified central station."

Who relies on it How Cite
SCIFs Extent 3 is mandatory. Contractor SCIFs "shall maintain a current UL certificate of installation and service," and the certificate is renewed after any IDS change. ICS 705-1; Tech Spec 7.A.2
SAPFs UL 2050 certificate with Extent 3; USG systems are exempt from certification DCSA SAP checklist F-30
NISPOM contractors IDS approval may be based on ICD 705, UL 2050 or CSA standards. The alarm company must be NRTL-certified. 32 CFR 117.15(d)
Contractors on DoD installations DCSA may accept a DoD IDS as an alternative under some conditions ISL 2014-03
AA&E Storage areas: Extent 2 or 3. Containers: Complete or Partial. Form CS-ASD-NISS
UL category (CCN) Meaning
CRZH National Industrial Security Systems: the alarm service company that installs, services and certifies UL 2050 systems
CRZM National Industrial Security monitoring station (NIMS)
CPVX / UUFX / CVSU Central-station burglar alarm service / protective signaling central station / residential monitoring station
CVSG Mercantile alarm service (UL 681), which is not UL 2050

Sources UL 2050 Ed. 6 catalog listing · UL Solutions: NISS certification · ICS 705-1 · DCSA SAP Compliance Checklist · 32 CFR 117.15 · DCSA ISL 2014-03

09.15

The CS-ASD-NISS form, the certificate and investigator response times

Workflow

  1. The CRZH-listed alarm service company fills out UL Form CS-ASD-NISS (Alarm System Description) for each protected area or container.
  2. The CSA representative signs for any item that needs prior approval. Under 32 CFR 117.15(d)(1), "CSA approval is required before installing an IDS."
  3. The company installs and tests the system, then issues the National Industrial Security System certificate through UL. Under 117.15(d)(5), the certificate is issued to the facility through the alarm service company and is "Subject to the NRTL inspection program whereby periodic inspections are made of representative alarm installations by NRTL personnel." The response time the CSA approved "will be noted on the alarm certificate" (117.15(d)(3)).
  4. Any change to the IDS after issue requires a renewed certificate (ICS 705-1).

What the form records:

  • Type of system: closed area, alarmed room, AA&E storage area, containers, GSA-approved container, or vault
  • Extent: closed area or alarmed room "3" or "5 (Prior approval is required)"; AA&E storage 2 or 3; containers and vaults Complete
  • Coverage and monitoring location
  • Line security: "None (Prior approval is required)", Standard, or Encrypted
  • Transmission method: data network requires prior approval
  • Investigator type
Investigator response option Condition (UL form or instructions)
5 minutes "applies to SAP or SCI systems"
15 minutes "the maximum time permitted for an investigator to respond to a signal is 15 minutes"
20 or 30 minutes Prior approval from the cognizant security office
60 minutes Contractor representative as primary investigator (prior approval)
Not stated A law-enforcement officer responds (prior approval)

Items that need a CSA signature: Extent 5, no line security, data-network transmission, law enforcement as monitor or investigator, and a 20- or 30-minute response.

Sources UL CS-ASD-NISS instructions (2019) · UL CS-ASD-NISS instructions (2024) · UL Form CS-ASD-NISS (2024) · 32 CFR 117.15 · ICS 705-1

09.16

UL audits and how to verify a UL 2050 certificate

How UL enforces the program. UL requires listed alarm companies to "successfully demonstrate compliance on an annual basis through an audit conducted by UL Solutions." Under 32 CFR 117.15(d)(5), certificates are also subject to the NRTL inspection program, in which representative installations are inspected periodically. An insurer's explainer (Hanover) says UL enters certificate reports into a database that insurers can check, and that UL spot-checks certificate holders.

Verify the company

  1. Search UL Product iQ, which replaced UL's Online Certification Directory. It is linked from UL's Code Authority page.
  2. Look for CRZH for the company that installs and services the system. If a NIMS monitoring station is proposed, also look for CRZM.
  3. Write down the file number shown on the listing.

Verify the certificate. UL's public demo certificate shows which fields to check:

Field What to confirm
File number and CCN Matches the Product iQ listing. The CCN is the national industrial category, not mercantile (CVSG).
Issue and expiration dates Current. The demo certificate expires one year after issue.
Protected property The accredited space
Each system Type of system, Extent 3, monitoring location, communication method, line security
Response time Matches the time the CSA or AO approved
Line security Encrypted, consistent with Tech Spec 7.A.3.b(10)

The last three rows come from Tech Spec and NISPOM requirements, not from UL's printed guidance.

Sources UL security alarm service certification · UL Code Authority (Product iQ) · UL demo certificate · 32 CFR 117.15 · Hanover: what is a UL alarm certificate (insurer)

09.17

UL 681 vs UL 2050 extents: what is and isn't known

UL's alarm certification program checks installations against UL 681, Installation and Classification of Burglar and Holdup Alarm Systems (Edition 15). It checks monitoring against UL 827, Central-Station Alarm Services. The CS-ASD-NISS instructions say the requirements for each national industrial extent level are "contained in UL 681." So the mercantile and national industrial programs use the same extent numbers.

Aspect UL 681 (mercantile, bank) UL 2050 (national industrial)
Purpose Controlling burglary and holdup losses, often driven by insurers Protecting classified material and AA&E as a government-required control
Who sets the extent Insurer or customer CSA or AO, through NISPOM, ICD 705 or DoDM 5205.07
Premises extents on public forms Mercantile worksheet (CS-ASD-BMR) offers 2, 3, 4; the demo certificate shows Extent 3 premises Closed area or alarmed room: 3, or 5 with CSA approval. AA&E storage: 2 or 3.
Safes, vaults, containers Complete / Partial Complete (containers, vaults); Complete or Partial (AA&E containers)
Listing CVSG, CPVX CRZH, CRZM
Government overlay None CSA signature. ICD 705 adds HSS Level II and motion at doors, 24-hour power, and FIPS/AES encryption.

What is public:

  • what "extent of protection" means
  • which extents each form offers
  • that Extent 5 relies on patrols and SID
  • that SCIFs and SAPFs require Extent 3

What is not public:

  • UL's own wording for each numbered extent, including Extents 2 and 4
  • the paragraph and table numbers in UL 2050 Edition 6
  • how a GSA container gets a "Complete" extent when the rule bars sensors on GSA containers

Sources UL security alarm service certification · UL CS-ASD-NISS instructions · UL demo mercantile certificate · UL Form CS-ASD-BMR · UL Standards catalog listing · 32 CFR 117.15

09.19

NISPOM 32 CFR 117.15 intrusion detection requirements

Terminology. The DCSA open storage guide says 32 CFR Part 117 "codified requirements for open storage areas and replaced 'closed areas' as an entity." UL's CS-ASD-NISS form still says "closed area," so the industry uses both terms.

Paragraph Requirement
117.15(d)(1) "CSA approval is required before installing an IDS." The basis can be ICD 705, UL 2050 or CSA written standards. Installation is by "an alarm services company certified by a NRTL that meets the requirements in 29 CFR 1910.7."
(d)(2) Allowed stations: GCMS, cleared commercial central station, cleared protective signaling service, cleared residential monitoring station, or national industrial monitoring station. Operators are SECRET-cleared. Alarm records are kept "for 12 months."
(d)(3) If the alarm resets and no damage is seen, uncleared responders may handle it. If it does not reset and damage is seen, a cleared team is dispatched, and the CSA gets a report if the team is not on site within 1 hour. "The requirement for response is 80 percent within the time limits." For TOP SECRET, the CSA may allow up to 30 minutes when environmental factors prevent the normal time.
(d)(4) Magnetic contacts on all points of probable entry, plus motion detectors in probable intruder paths. Lines "electronically supervised to detect evidence of tampering or malfunction." "No IDS sensors (magnetic contacts or vibration detectors) will be installed on GSA-approved security containers."
(d)(4)(i)–(v) CSA authorization is required for: no line security (then two independent means of transmission are required); Extent 5; law enforcement as primary responder; transmission "over computer-controlled data-networks"; investigator response longer than the limits
(d)(5) A valid, current NRTL certification for the right category of service

Storage rules (32 CFR 2001.43):

  • TOP SECRET open storage: IDS with a 15-minute response when SID is present, or a 5-minute response without SID.
  • SECRET: IDS with a 30-minute response, or inspections every 4 hours.
  • DCSA "will not approve the space if acceptable SID is not established unless there are onsite employees or guard services to meet the 5-minute response time required."

Sources 32 CFR 117.15 · 32 CFR 2001.43 · DCSA open storage approval guide · DCSA ISL 2006-02

09.20

SAPF intrusion detection under DoDM 5205.07 and the DCSA checklist

Current manual. DoDM 5205.07, Special Access Program Security Manual, took effect 17 January 2025. It is a combined manual that "incorporates and cancels" Volume 3 (Physical Security, 23 April 2015). Physical security is now Section 15, "Physical Security Procedures." The SAPF-AO "is responsible for reviewing and approving or disapproving physical security preconstruction plans for, and physically inspecting and accrediting, reaccrediting, and de-accrediting, a SAPF."

In practice, SAPF IDS follows Tech Spec Chapter 7. DCSA's January 2026 SAP compliance checklist (v2) cites Chapter 7 paragraphs throughout:

Item Requirement Tech Spec
F-26 SAPF protected by IDS and tested semiannually 7.A.1.a; 7.D.3.b
F-27 Test records kept 2 years 12.L.6
F-28 Each failure to arm or disarm reported to the GSSO/CSSO; records kept 2 years 7.B.3.c
F-29 Entrance delay ≤ 30 seconds 7.A.3.a.6
F-30 "Does the SAPF IDS have a (UL) 2050 Standard certificate with Extent 3 installation for IDS components and monitoring stations?" 7.A.2.a–c
F-32 U.S. companies using U.S. citizens 7.D.1
F-41 Closed storage: 15 min. Open storage: 15 min with SID, 5 min without. 3.H
F-42 External response agreement: response time, duties, points of contact, time on site 12.L.2
F-43 Station supervised by trained U.S. citizens eligible for SECRET 7.B.6.b
F-44 24 hours of uninterruptible backup power, documented in the FFC 7.B.5.b

CDSE SA501 (Nov 2024): "SAPF construction requirements require the use of UL Level II HSS. In existing facilities, the use of existing UL Level I HSS are authorized until major IDS modifications or upgrades are made."

Sources DoDM 5205.07 (2025) · DCSA SAP Compliance Checklist (Jan 2026) · CDSE SA501 · DoDM 5205.07 Vol. 3 (cancelled)

09.21

Communicators, line security and the FIPS 140-2 transition

Tech Spec baseline

  • Panel to station: transmission uses NIST FIPS-certified encryption. A UL 1610 listed PCU needs FIPS 197 (AES) or FIPS 140-2. A UL 1076 listed PCU needs FIPS 140-2. Any other method needs AO approval, noted on the certification (7.A.3.b(10)).
  • LAN/WAN: FIPS 140-2, VPN, or closed and sealed conveyance. FIPS 197 is allowed with AO approval (7.A.3.c(2)(g)).
  • Secondary paths: supervised like the primary. A wireless or cellular secondary path needs AO approval after consulting the CTTA (7.A.3.c(2)(d)).
  • NISPOM: "None" for line security needs CSA approval plus two independent transmission paths. Data-network transmission needs CSA acceptance criteria (117.15(d)(4)(i), (iv)).

Algorithm vs. module. FIPS 197 is the AES algorithm standard. FIPS 140-2 and 140-3 validate cryptographic modules. The Tech Spec mixes the two, so ask the vendor for the CMVP module certificate, not just the word "AES."

The 2026 transition. NIST's CMVP stopped accepting FIPS 140-2 submissions on 1 April 2022. FIPS 140-2 validations move to the Historical List on 21 September 2026; the NIST schedule table also shows 22 September 2026. NIST says: "Even on the historical list, CMVP supports the purchase and use of these modules for existing systems."

Supervision interval. Older DCSA guidance polled every six minutes. The Tech Spec mentions "communication failures less than five minutes" when explaining secondary paths. Confirm the interval your AO or CSA expects.

Sources IC Tech Spec Ch. 7 · 32 CFR 117.15 · NIST FIPS 140-3 transition · DCSA ISL 2006-02 · SCIF Fixed Facility Checklist v1.5

09.22

SCIF vs SAPF vs NISPOM open storage vs GSA container

Attribute SCIF SAPF NISPOM open storage area GSA container (contractor TS/S)
Approves IC element AO SAPF-AO DCSA approves the area and the IDS before installation DCSA (supplemental controls)
IDS required When unoccupied When unoccupied TS: yes. Secret: IDS or 4-hour checks. TS: IDS, 2-hour checks, or SID plus an FF-L-2740 lock. Secret: no supplemental control.
UL level Extent 3 Extent 3 (F-30) Extent 3; Extent 5 only with CSA approval System type "GSA approved container," extent Complete
Door sensors UL 634 Level II HSS plus motion on every perimeter door Same Magnetic contacts on all points of probable entry No sensors on the container itself
PCU Inside the SCIF Same Covered by UL 2050
Backup power 24 h 24 h (F-44) Per UL 2050 Per UL 2050
Line security FIPS encryption or sealed conduit Same Required. "None" needs CSA approval and dual paths. Same as NISPOM
Response force Closed: 15 min. Open: 15 min with SID, 5 min without. Same (F-41) TS: 15 min with SID, 5 min without. Secret: 30 min. 80% rule. TS: 15 min
Cleared follow-up SCI-indoctrinated person within 60 min, or AO-approved time Same Cleared team if the alarm doesn't reset and damage is seen; report if not on site within 1 h Same as NISPOM
Station staff U.S. citizens eligible for SECRET Same (F-43) SECRET-cleared operators Same as NISPOM
Testing Acceptance test plus semiannual; 3-of-4 walk test Semiannual (F-26) Per UL 2050 Per UL 2050
Records 2 years 2 years (F-27, F-28) Alarm records 12 months 12 months

Sources IC Tech Spec Ch. 7 · DCSA SAP Compliance Checklist · 32 CFR 117.15 · 32 CFR 2001.43 · UL CS-ASD-NISS instructions · DoDM 5205.07 (2025)

09.23

Common IDS findings at accreditation

# Finding Requirement broken
1 Perimeter door has an HSS but no motion coverage, or motion but only a standard contact 7.A.3.a(7)
2 Level I or non-UL 634 switch on a new accreditation 7.A.2.d
3 PCU or keypad outside the SCIF, or arm state can be changed from outside 7.A.3.b(1); FFC Sec. E
4 Sensor cable above a corridor ceiling with no encryption or sealed ferrous conduit; set-screw EMT fittings 7.A.2.e
5 Entry delay over 30 seconds; auto-reset left on 7.A.3.a(6); 7.A.2.m
6 Installer or master codes left at factory defaults 7.A.3.b(11)
7 Batteries last less than 24 hours, or no calculation in the FFC 7.B.5; F-44
8 Communicator not FIPS-certified, or data path not approved 7.A.3.b(10); 117.15(d)(4)(iv)
9 IDS shares a panel with fire or water systems 7.A.2.h
10 Video-verified motion sensors, or devices with microphones, without AO approval 7.A.2.l
11 Walk test not done with the four-step, 3-of-4 method 7.D.3
12 Certificate missing, expired, mercantile, not Extent 3, or not renewed after changes 7.A.2.a–b; ICS 705-1

BMS alignment. Mount the switch on the secure side and keep it within the manufacturer's gap tolerance. Door sag, weather-strip compression and acoustic gaskets shift the gap over time.

Motion above ceilings and below raised floors. UFC says this is not normally required. It may be required at overseas Category I and II sites, or when the AO decides. Expect the AO to require plenum motion or another fix in two cases: the perimeter wall stops at the drop ceiling instead of the true deck, or a raised-floor plenum connects to non-SCIF space. Settle this on the pre-construction checklist.

Ducts. Openings larger than 96 square inches need bars, grilles or metal baffles, unless one dimension is under 6 inches (3.G.7.c). IDS is not listed as a substitute, so do not design in-duct motion as the fix without written AO approval. See: Penetrations, Utilities & Life Safety.

Sources IC Tech Spec Ch. 7 · UFC 4-010-05 · SCIF Fixed Facility Checklist v1.5 · 32 CFR 117.15 · KL Security: SCIF IDS (practitioner)

09.24

Vetting a UL 2050 alarm company

  1. Listing. Confirm the company is listed as CRZH in UL Product iQ, and CRZM for a NIMS station. Write down the file number.
  2. Track record. Ask for a redacted sample UL 2050 certificate and a description of the company's CS-ASD-NISS process. Confirm it has done Extent 3 closed-area work and SCIF or SAPF accreditations.
  3. Monitoring. Confirm the station type (GCMS, NIMS or UL central station) and that operators are U.S. citizens eligible for SECRET. If the AO requires a 5-minute response, confirm who provides the on-site response.
  4. Clearances and contracts. Monitoring by a cleared commercial station involves government sponsorship, typically a DD Form 254, and clearance processing that UL does not control.
  5. People. A U.S. company using U.S. citizens for installation and testing (7.D.1). Maintenance technicians TOP SECRET-cleared or escorted (7.C.2). The DISA Traditional Security Checklist also checks "IDS Installation and Maintenance Personnel - Suitability Checks."
  6. Service. Put service start within 4 hours of a trouble signal (7.C.2) in the contract.
  7. Encryption. Ask for the communicator make, model and CMVP certificate, and check its FIPS 140-3 status.
  8. Sequencing. Get CSA or AO approval before installation (117.15(d)(1); 7.A.2.o). Practitioners trace accreditation failures to "design decisions made without reference to ICD 705… and documentation gaps that emerge too late to fix."
Red flag Why it matters
Offers a mercantile certificate Not a UL 2050 certificate
Proposes Extent 5 for a SCIF or SAPF Not allowed under ICD 705
Wants remote programming with no network monitoring plan 7.A.3.c(2)(c)
Cannot name the monitoring station or say whether its operators are eligible for SECRET 7.B.6
Calls a panel or sensor "UL 2050 listed" UL 2050 certifies service, not products

Sources UL Code Authority (Product iQ) · Security Systems News: UL 2050 rules · IC Tech Spec Ch. 7 · 32 CFR 117.15 · Cencore: ICD 705 Tech Spec explained (practitioner) · NIST FIPS 140-3 transition · Traditional Security Checklist (stigviewer)